who_need_help/docs/google-provider-inventory.md
SimpleTest 319cdb970b
Some checks are pending
Quality / full-local-gates (push) Waiting to run
Document test Firebase and OAuth configuration
2026-08-28 19:45:24 +03:00

161 lines
8.5 KiB
Markdown

# Google provider inventory
Verified read-only on 2026-08-28 against the authenticated Google Cloud and
Firebase consoles, the local Dev `.env`, the installed Test and Prod `.env`
files over SSH, and the repository environment validators. No secret values
were read into this document. This is an inventory, not a source of secrets.
## Environment contract
Who Need Help has exactly three deployment environments:
| Environment | Public origin | Android build/package | Google project |
| --- | --- | --- | --- |
| Dev | `https://whoneedhelp.imalto.site` | `development` / `org.whoneedhelp.mobile.development` | `Who Need Help Development` / `who-need-help-development` / `299749044449` |
| Test | `https://test.whoneedhelp.com` | `staging` / `org.whoneedhelp.mobile.staging` | `Who Need Help Staging` / `who-need-help-staging` / `340523338913` |
| Prod | `https://whoneedhelp.com` | `release` / `org.whoneedhelp.mobile` | `Who Need Help Production` / `who-need-help-production` / `184178014037` |
`staging` is only the existing Google display name and Android build/package
label for **Test**. It is not a fourth environment. Reuse the three project IDs
above; do not create another Google Cloud or Firebase project for these
environments.
The active promotion workflow is:
1. Develop and verify on Dev (`whoneedhelp.imalto.site`).
2. Promote the exact candidate to Test (`test.whoneedhelp.com`) and repeat the
application, provider, and browser checks there.
3. Promote that exact verified candidate to Prod only after explicit operator
approval.
The previous Build Week restriction on changing Test has ended. Test is the
normal pre-production verification environment; Prod is never updated as an
implicit consequence of a Dev or Test deployment.
The repository enforces this mapping in
[`scripts/validate-android-environment.sh`](../scripts/validate-android-environment.sh).
The installed runtime identifiers match the table: Dev points to
`who-need-help-development`, Prod points to `who-need-help-production`, and
Test points to `who-need-help-staging`. The Test `.env` contains the validated
Firebase Android and server-side FCM settings, but the currently running Test
container must be replaced by a verified Test release before it can consume
those values.
## Current registrations
### Dev
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-development)
- Web: `Who Need Help Development Web`
(`299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com`)
- origin: `https://whoneedhelp.imalto.site`
- callback: `https://whoneedhelp.imalto.site/auth/google/callback`
- Android: `Who Need Help Development Android`
(`299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com`)
- [Firebase project](https://console.firebase.google.com/project/who-need-help-development/settings/general):
Spark, shown as `No-cost ($0/month)` at verification time.
- Firebase Android app: `Who Need Help Development`, package
`org.whoneedhelp.mobile.development`, app ID
`1:299749044449:android:284bfd48e072ca29e307a0`.
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-development):
- `wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.com`
is enabled for FCM HTTP v1;
- the Firebase Admin SDK service account exists and has no user-managed key.
### Test
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-staging)
- Web: `Who Need Help Staging Web`
(`340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com`)
- origin: `https://test.whoneedhelp.com`
- callback: `https://test.whoneedhelp.com/auth/google/callback`
- Android: `Who Need Help Staging Android`
(`340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com`),
package `org.whoneedhelp.mobile.staging`.
- [Firebase project](https://console.firebase.google.com/project/who-need-help-staging/settings/general):
Firebase is enabled on the existing Test Google Cloud project. No separate
Google Cloud project was created.
- Firebase Android app: `Who Need Help Test`, package
`org.whoneedhelp.mobile.staging`, app ID
`1:340523338913:android:f6f7f7780c1b4a6258f4e0`.
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-staging):
`wnh-test-fcm-sender@who-need-help-staging.iam.gserviceaccount.com` has the
`Firebase Cloud Messaging API Admin` role. The FCM API is enabled and the
account has exactly one active user-managed key. The key material is stored
only in ignored, mode-`0600` provider/runtime configuration and is not
documented here.
- The Google Cloud project has a billing account linked. The console showed
`$0.00` estimated charges for 2026-08-01 through 2026-08-28; this observation
is not a pricing guarantee.
- The only supported Test callback is
`https://test.whoneedhelp.com/auth/google/callback`.
- The retired `https://staging.whoneedhelp.com/auth/google/callback` entry was
removed from the Test Web OAuth client on 2026-08-28. Do not recreate or use
it.
### Prod
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-production)
- Web: `Who Need Help Production Web`
(`184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com`)
- origin: `https://whoneedhelp.com`
- callback: `https://whoneedhelp.com/auth/google/callback`
- Android clients: `Who Need Help Android Upload`,
`Who Need Help Android Play RSA 1`, `Who Need Help Android Play RSA 2`, and
`Who Need Help Android Play ML-DSA`.
- [Firebase project](https://console.firebase.google.com/project/who-need-help-production/settings/general):
Spark, shown as `No-cost ($0/month)` at verification time.
- Firebase Android app: `Who Need Help Production`, package
`org.whoneedhelp.mobile`, app ID
`1:184178014037:android:18b3996444c3bebce361dc`.
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-production):
- `who-need-help-fcm@who-need-help-production.iam.gserviceaccount.com` is
enabled for FCM HTTP v1;
- the Firebase Admin SDK service account exists and has no user-managed key.
- [Google Play app](https://play.google.com/console/u/0/developers/5283023225403815420/app/4972430103169452589/app-dashboard)
is the production Android application.
- Four Android OAuth clients currently exist while the local Play identity
inventory records three Play signing identities. The purpose of the fourth
client has not been verified; do not delete or merge any of them based only
on their similar names.
## Configuration ownership
Each checkout keeps one ignored `.env`. Provider secrets must remain there or
in the ignored provider files consumed by the import scripts; never copy them
into this document or commit them.
| Capability | Runtime configuration |
| --- | --- |
| Web Google sign-in | `GOOGLE_OAUTH_CLIENT_ID`, `GOOGLE_OAUTH_CLIENT_SECRET` |
| Android Google sign-in | `GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS` |
| Public Firebase Android config | four `WNH_FIREBASE_*` values |
| Server-side FCM | `FCM_PROJECT_ID` and exactly one service-account source |
| Android App Links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` |
Relevant validated importers:
- [`scripts/import-firebase-android-config.sh`](../scripts/import-firebase-android-config.sh)
- [`scripts/import-fcm-service-account.sh`](../scripts/import-fcm-service-account.sh)
- [`scripts/import-play-android-config.sh`](../scripts/import-play-android-config.sh)
An FCM sender account and runtime configuration prove registration only;
delivery still requires the matching deployed environment and an actual
device smoke test. Test is registered and configured, but its running
container and Android build have not yet completed that delivery smoke test.
The ignored `tmp/environment-access/*.env` files are historical snapshots, not
live configuration. In particular, its old Dev snapshot still references the
historical `who-need-help-dev-firebase` setup and must not be used to recreate or
overwrite the current Dev configuration.
## Do not recreate
- Do not create a fourth environment called Staging.
- Do not create another Firebase project for Dev or Prod.
- Do not place OAuth client secrets, Firebase API keys, service-account JSON,
private keys, or key IDs in documentation.
- Do not delete an OAuth client, callback, Firebase app, fingerprint, or service
account until its active environment and signing identity have been verified.